vote-navis[.]pages[.]dev
“NAVI”
已存储的观测记录
观测到的标题差异
证据摘要
PhishDestroy identifies vote-navis.pages.dev as a high-risk crypto wallet drainer posing under the guise of a legitimate service. This domain was flagged due to its active role in cryptocurrency theft, specifically designed to deceive users into connecting their wallets under false pretenses. Upon connection, the drainer silently siphons funds from unsuspecting victims, often mimicking popular crypto platforms or tools to gain trust. The domain operates under Cloudflare's infrastructure, leveraging their CDN and security features to obscure its true origin while maintaining accessibility. Such drainers are notorious for their low initial detection rates, relying on the delay between discovery and flagging by security services to maximize their victim pool. This domain exhibits several technical red flags that warrant immediate caution. Registered through Cloudflare, Inc., vote-navis.pages.dev resolves to the IP address 188.114.97.3 and is secured with a Google Trust Services SSL certificate, which lends it a veneer of legitimacy. However, VirusTotal currently reports 1 out of 95 antivirus engines detecting it as malicious, a common characteristic of newly deployed or stealthily operating drainers. Cloudflare's infrastructure further complicates tracking, as it masks the domain's true hosting location and ownership details. The absence of detections does not equate to safety; instead, it highlights the domain's effectiveness in evading early-stage detection mechanisms, emphasizing the need for proactive verification tools like PhishDestroy. Users who have interacted with vote-navis.pages.dev should act swiftly to mitigate potential losses. First, disconnect any connected cryptocurrency wallets or revoke any permissions granted to untrusted domains through tools like WalletConnect or your wallet's built-in dApp browser settings. Next, transfer remaining funds to a new, secure wallet to prevent further unauthorized access. Finally, scan your device for malware or malicious browser extensions that may have been installed during the interaction, as drainers often bundle additional payloads. PhishDestroy strongly advises against entering any credentials or connecting wallets to domains that have not been independently verified. Report this domain immediately to PhishDestroy and relevant crypto communities to aid in its deactivation and to warn others. Remaining vigilant and verifying URLs before interaction is the most effective defense against such crypto drainers.
Data Coverage
网络安全情报
| Detection System | Indicator | Verdict | Alert |
|---|---|---|---|
| Nextron YARA rules | vote-navis.pages.dev/assets/secure.php?req=ping |
malware | PHP webshell obfuscated by encoding of mixed hex and dec |
| Nextron YARA rules | vote-navis.pages.dev/assets/secure.php?req=ping |
malware | Known PHP Webshells which contain unique strings, lousy rule for low hanging fruits. Most are catched by other rules in here but maybe these catch different ver |
威胁响应 Pipeline
阻止列表覆盖
监控中的外部数据源 10 个 · 已存快照 2026年8月11日
技术
识别出 4 项高置信度技术
VirusTotal 分析
网站性能分析
Google PageSpeed Insights — mobile performance audit of vote-navis.pages.dev · checked May 11, 2026
您是否受到本网站的影响?
如果您输入了帐户凭据、个人或付款信息,或者从此域下载了文件,请立即采取措施。以下资源可帮助您报告事件并保护自己。
检查任意域名
使用存储的阻止列表、WHOIS、DNS 和公共扫描证据进行威胁分析
立即扫描举报网络钓鱼
将可疑域名提交至我们的威胁数据库——保护社区
报告实时威胁动态
最近的网络钓鱼报告和观察到的可用性变化
监控